Soft Skills Engineering - Episode 145: What to do with a bad manager who is loved by upper management and should I include detecting major security vulnerabilities on my resume?
Episode Date: February 18, 2019In this episode, Dave and Jamison answer these questions: How do I deal with the manager on my team who is both not very technical and positions himself as the “boss” spending almost no t...ime with the team (except dragging everyone into more and more meetings! 😡) . My manager upsets and demotivates the team but not upper management and is clearly trying to climb the career ladders as fast as possible. Obviously everyone wants the team to succeed but the friction is growing. Some team members already left with (maybe too subtle) hints at the problem. Should one stage a coup and take over? Silently manipulate people to go to into “the right” direction? Switch teams/jobs and see it burn from the sidelines 🍿? While testing my system at work, I was shocked how little security there was. Two issues exposed the entire system’s data by just changing the query string. Also every API call had no backend check on the user making the call. These are just two examples of many. This is at a gigantic multi billion dollar institution handling hundreds of thousands of people’s data, some of it incredibly sensitive. This fact will be known on my resume. This leads to my question: I am looking for a new job now, and wondering how much detail about these security issues is appropriate to share on a resume? I feel this helps me stand out as a newer dev, but would this be frowned upon by prospective employers that may worry I might overshare their own security issues? Thanks for all your help!
Transcript
Discussion (0)
It takes more than insane debugging skills to be a great software engineer.
This is Soft Skills Engineering episode 145.
I'm your host, Dave Smith.
I'm your host, Jameson Dance.
Soft Skills Engineering is a weekly advice show for software developers about non-technical
subjects.
I guess it's like debugging people problems or organizational problems.
Yeah, it's true.
It's like root cause.
Yeah.
I want to thank our wonderful patrons.
Thank you so much to Chris Hogan, the Agile Ventures charity, Zach Grannon, David Jackson,
Sean Clayton, Nick Kantar, and Sonic the Hedgehog.
Thank you for supporting the podcast at the level where we shout you out every single episode.
If you want to support the show, you can go to softskills.audio and click support us on Patreon.
All right.
Do you want to jump into our questions?
Let's do it.
Let's just do it.
Down to business.
All right.
I'll read the first one.
This comes from an anonymous listener who says,
How do I deal with the manager on my team who is both not very technical and positions himself as the, quote, boss,
spending almost no time with the team except dragging everyone into more and more meetings?
Angry red face emoji.
i'm always bad at saying the emoji names i think you have a second career ahead of you as an emoji
transcriber setting a new bar for low quality emoji transcription all right continuing my manager
upsets and demotivates the team but not upper management and is clearly trying to climb the
career ladder as fast as possible obviously everyone wants the team to succeed but the
friction is growing. Some team members have already left with maybe too subtle hints at the
problem. Should one stage a coup and take over or silently manipulate people to go into the right
direction or switch teams jobs and see it burn from sidelines? Popcorn emoji. You got it. Nailed
it. I love that. Just the mental image of you eating popcorn and watching this other team crash
burn is just so sadistic i mean if there's a team out there that pays you to eat popcorn
switch immediately that sounds like that sounds like the deal of a lifetime you don't even have
to do any work and it can be celebratory popcorn it doesn't necessarily need to be like uh watch
disasters occur maybe they just have too much popcorn and they need to get rid of it it's a
popcorn surplus yeah huh so non-technical manager who is causing the team pain but it appears like
upper management is not aware of the pain and they like this person even though the team is
struggling underneath them yeah and and this is a very ambitious manager who's climbing the ladder
which tells me that you might not be uh in the situation for long it sounds like you might just
climb that ladder ran up up to the next rung and be out of your hair this is this just my justice
meter is like waving wildly i i have this this desire for the world to be good and just and i
want people to get promoted that kick butt at their current job not people to be promoted who
are good at climbing the ladder and ambitious if that makes sense like the fact that the team is
sad and people are quitting makes me makes me want to have this person not succeed yeah but
it's very possible that the path to promotion is very different from what is required to be
good at your job and do good work which just it just hurts i know hurts me that the world is like
that me too well what meditations on bureaucracy excuse me i'm gonna go get some popcorn that
section yeah what should they do this is really hard because i think you're faced with a dilemma
of do i just bear it and just deal with it or do i let this in or do i actually tackle this
injustice and then you have to ask yourself if i tackle this injustice and go to my manager's
management and ask them to do something and give them enough evidence to take action and move this
person out you could i mean now you're rolling the dice again and you're you may be getting a
new person entirely who's bad in all kinds of new ways and so do you keep the same you jumped way
ahead yeah i mean that's that's if it works oh yeah i mean if you if your efforts result in
them not being your manager anymore yeah good that's a fair point and that's a big if
big big assumptions but assuming all that comes together you still might end up with a replacement
who's just as bad in maybe a different way as this person so so you either in my opinion go
for the gusto all the way and try to get this person displaced or you learn to work around
this person's idiosyncrasies that's like a diplomatic way of saying terrible attributes
work around them like you would work around a bug in software and then just move on and those are
your two options i think i don't know is there a third option i'm not seeing i just idiosyncrasies
is like you wear a funny hat sometimes uh so the two options are work around them or roll the dice
and try to get them replaced by someone else basically right yeah is that what you're saying
i think you should also be aware everyone knows whistleblowers just they retire to a life of
luxury yeah and are just like their names echo through the company as people who have done great
things and everyone loves them oh yeah there's a chance that not only will you not get this person
replaced but that it can backfire oh yeah wildly as as you try to work around them or or disrupt
them or i don't know undermine them yeah i mean this this person is clearly dead set on climbing
the latter and if you step in and disrupt that you could incur the ire of a very ambitious and
focused person yeah i think i think if you do want to take that approach you have to make it about
results not about things that you don't like about them if they're rude or or i don't know
whatever their idiosyncrasies are but if you can make it about how the team is not delivering
because of this person that's a lot easier to uh i think it's a lot less objective it's a lot
or the other thing it's a lot more objective it's a lot less likely to appear like oh they
just don't get along right like a personality conflict yeah yeah if you can say here's how
their bad behavior is causing the team to fail at meeting our objectives and goals
then i think that's the stronger case than saying the team is unhappy even though the team is unhappy
is very valid criticism and feedback it might be harder to receive in this kind of fraught
environment than yeah we fail at our projects because of this this and this that this person
does yeah and also keep in mind that there might be a silver lining here if this manager is really
good at making management think he's great then management through the transitive property of
greatness might think your whole team is great and it could very well be that he is setting you up
for long-term success in the organization by creating positive marketing around your own
team within the company. And so I wouldn't completely discredit this person as a manager
just because he doesn't manage down very well. He could be that he's managing up super great
and you might just benefit from it. Yeah. I feel like kind of reading between the lines,
I wonder if it's applying a lot of pressure and kind of like cracking the whip to make people
crank stuff out because that's the thing that could cause a lot of friction with the team.
but be appreciated by upper management.
And then you have a harder time saying like,
we're failing because they'll be like,
you're not, you're doing great.
All those 80 hour weeks are really paying off.
Yeah.
And I told your manager to do that.
Yeah.
Yeah.
Huh?
I don't know.
I do think you need to take a holistic view here
and not just consider how you and your team
react to your manager,
but consider the whole enchilada
and see if maybe there's some benefits.
And then if you're really proactive,
what you could do with your manager
is you could sit down and say, here are your strengths, here are my strengths, and the rest
of the team's strengths. Let's see if we can create a complementary team where you play to
your strengths and we play to ours. And here's how we want the relationship to work from you
downward. And then, you know, let's see if we can make this awesome together. Yeah. Upsets and
demotivates the team. That feels like a key phrase. I wonder if they're aware and they're just
willing to do it because it's the cost of climbing the ladder. You mean you wonder if
they're a psychopath yeah kind of or or maybe they're not aware and then there is more room
for conversation kind of like you suggested to say hey that if you want to climb the ladder like
having us do great work is one way to do that and these things are preventing us from doing great
work yeah you could kind of make it make it clear how it will help them achieve their goals oh yeah
good point that's that's really important i think yeah i don't know this is a tricky problem
a non non-technical manager do you think that plays into it the fact that they're not technical
oh i think that could definitely play into it it could it could even bias the question asker
against this person's skills because their skills are not as apparent in the technical domain
oh that makes sense you're saying it's possible that they are good at things that you don't
see right do you think it is worth asking your boss hey what do you do what is your day like
where does your time and effort go i think that question might be a little too specific
might cause an eyebrow to go up i mean obviously snuck in between just comments about sports teams
yeah it's a combination of the weather and sports where you actually play a sports game
based on the weather it's the ultimate small talk topic cloud fight thunderball
boy how about that cold front out of minnesota that is leading the standings
oh my gosh uh fantasy weather leagues that's got to exist there has to be like futures markets
oh there are there are futures markets on weather there are there absolutely are okay
well i'm gonna go dominate them but there's no fantasy weather league as far as i know
i played it's sort of the same thing right it is i guess it's just yeah you just don't have
to have a phd in finance to play one of them yeah okay but i feel like my my my original point
still could stand maybe maybe maybe there's room to better understand what they do and why
because it's possible you have a biased view of it
and you don't understand kind of the value
of the things that they're doing.
It's possible that you could find out
and then be like, yeah, yeah, I was totally right.
It's useless political nonsense
that just hurts the team and helps themselves.
But it might be worth exploring a little bit too.
I have had a conversation like this with a manager
who was spending time, or rather,
whose actions day by day were less visible to me
than I cared for.
I just didn't really know what they did with their time.
And I asked them, I didn't ask them, where do you spend all your time?
But I did ask them, how do you see your role?
And at the time, I was a technical lead on the team with this manager.
And I said, how do you see your role compared to mine?
What are the things you do and I don't?
And he actually listed several things that I hadn't even considered that he considered
to be important parts of his job.
And after he said it, I was like, oh, you're right.
Those are important things.
I just didn't even think.
Yeah, you can keep doing those.
I don't want to do any of those things.
Yeah, yeah.
Not only are they important.
i don't want to touch him and it gave me a new perspective on him so maybe maybe that kind of a
conversation would be that would be valuable here well have we helped probably not this is a tricky
one i i think switch jobs is always an option too yeah i've heard the saying people quit managers
they don't quit jobs and i could see that so maybe it's time i don't know all right good luck next
question i am going to just read it this is from another anonymous listener while testing my system
at work i was shocked by how little data security there was two issues exposed the entire system's
data by just changing a query string also every api call had no back-end check on the user making
the call these are just two examples of many this is a gigantic multi-billion dollar institution
handling hundreds of thousands of people's data some of it incredibly sensitive this fact will
be known on my resume. This leads to my question. I am looking for a new job now and wondering how
much detail about these security issues is appropriate to share on the resume. I feel
like this helps me stand out as a newer developer, but could be frowned upon by
prospective employers that worry that I may overshare their own security issues. What should
I do? Thanks for your help. This is very simple. As you are applying for new companies, go to their
website and find all the security issues there, and then just blackmail your way into that job.
I mean, that's kind of tongue in cheek, but I feel like that's a great way to get a security job
at the right organization, or potentially go to jail at the wrong organization.
And learn about a whole new kind of security, maximum security.
You know, at my last company, we were hiring an InfoSec, what do we call this person?
chief security officer i think and we were a small startup we had about maybe 50 people
in the office there and uh he had an interview schedule for later in the week but he showed up
a couple of days early and just walked in to see how far he could get into the office
and he started asking people questions and stuff and he actually did get stopped by one of the
employees um but it was just hilarious and then when he came into the interview he was like hi
everyone and they were like oh we remember you it was a crack you get the job he did and he's
still working there five years later all right proof positive so you could get a job at your
current company is what dave is saying as a security researcher yeah that's tricky i think
it's worth mentioning that you have found vulnerabilities but probably not what they are
if you if you include like a working python script to reproduce them that's probably not great
uh yeah definitely so so you're saying there's a line gigantic like universe-sized caveat here i
am not a security expert and this is this is not my domain and there are probably procedures about
how to handle security vulnerabilities and so i think my meta advice is like talk to someone in
a security field to ask what they think about how to handle this situation yeah i mean there's
whole like common vulnerability what's the cv what does the e stand for i don't know i was
actually just looking at one yesterday and really i'm trying to realize exchange trying to recall
what the e stands you swap them with each other i don't know but but yeah they're like mailing
lists and processes and stuff to to expose vulnerabilities and projects so there's probably
some precedent about how to handle this but pretend like you don't want any of that stuff
You want our advice on this.
I, on the other hand, am an intergalactic security expert.
Oh, wow.
Wow.
I had no idea.
All right.
Tell me.
Just tell me what to do.
I can't even.
Your language doesn't even work to talk about the security that I know.
It's just lost in the translation.
But seriously, here's what I know about security.
any comment any statement you make about security there is someone waiting in the wings
to poke their head out and say well actually and then like you just can't make any assertions
yeah okay well actually caveat is is is there i mean i think you can mention i found all these
vulnerabilities but not say what they are and and then be prepared to talk about them in vague
generic terms that aren't like how horrible the company was but more like look at how this
demonstrates my skills at problem solving because that's what you're trying to do exactly in fact i
would focus on what you did to resolve these issues and i would say something like i fixed
x number of security vulnerabilities and protected the data of you know significant data for the
company and you probably would be it would probably be inappropriate to disclose like
you know if you said something like four million customers would have had their credit cards leaked
or something like that that would probably be inappropriate what if they didn't fix it though
what if they just found it i'm imagining a nightmare scenario where it's a giant institution
so there's probably a lot of bureaucracy what if they try and report it and then it just gets
smacked down someone jedi mind tricks them and says there are no security vulnerabilities
I would probably leave that off my resume
leave the part about how you didn't fix it or just leave the part about how you found it
off yeah like I might just leave the whole thing off because it's going to lead to a story of
well what happened and then and then you're going to have to tell this story about how
there are still security vulnerabilities at your previous company that are unfixed
and you were you were unable to influence the organization to fix them I mean there's detail
we didn't read that basically they were not a security person at all this is pretty far outside
of their wheelhouse though true so do you feel like it's a reasonable expectation to put on them
to say that you you should fix whatever you find like well i'm not i'm not saying i expect you to
fix it but i am saying if you're going to call it out as a big plus on your resume it should probably
have a really strong story to go with it and okay if if you have to then describe it to a potential
employer and they're like what happened you're like well i couldn't get it done you know i mean
that's the story that they're going to hear. Hmm. Okay. That's interesting. So it's, it sounds like
almost a failure then. Yeah. Like, I mean, to me, every bullet on your resume should be
just a fabulous story about you that makes someone want to hire you. Um, that doesn't mean that you
haven't done anything wrong. It just means that if you're going to sell yourself, you should
probably put your best feet forward. Hmm. I only have two feet and I usually put them both forward.
That's, that's way more of a bummer than what I thought you were going to say.
what did you think i was gonna say i don't know it just seems like it's like a cool accomplishment
hey i'm in this other role and i was poking around and i uncovered this pretty big thing and here's
here's what i used or here's the skills i used to investigate it and i guess i can see there's
nothing else to say after that if you didn't resolve it or didn't cause it to get resolved
i mean finding issues is great but if you found an issue and remember i know nothing about your
company and so if you found this big issue and then and for whatever reason the company decided
not to fix it i could interpret that as well you found an issue but it wasn't that important
because the business didn't invest in fixing it yeah you know and it's like are you going to come
to my company and just poke around and do stuff that's useless from a business perspective or are
you going to come and do valuable stuff for my business so anyway so you you have the opportunity
to do some resume driven development then if you're still there you could you could push a
little bit more to get it fixed yeah and then and then and ending for your story then you quit and
Now, I don't think this is written in the question.
So we may be a little bit on a tangent here, which, by the way, I think we should consider renaming the podcast to just tangent.
But anyway, just one word, one word.
But like so let's let's assume that it does have a happy ending.
The real crux of this question is, am I ethically bound to not disclose these security vulnerabilities from an institution I worked at that has a reputation to uphold?
I don't know. I don't think so. I feel like if it's work that you did that was valuable, there are security vulnerabilities everywhere. And I think not being able to say how you improved the state of things because it would prove that things were bad before, that doesn't feel right to me.
I mean, I do feel pretty strongly that you shouldn't get into the specifics of talking about what system it was or what, like you said, what data was exposed or maybe even how exactly it worked or how someone could reproduce it.
But I don't see how, I mean, most of the work that most people do every day is somehow to, most developers do is to improve some system, right?
And like you should be able to talk about that work without feeling like you're implicitly saying, boy, it was really sucky before.
And then and then worrying that people are going to think you're talking crap about your your current employer.
True. I mean, but I do think let me ask you this.
Do you think there's a difference between me saying, for example, I made the software run twice as fast and improve the lives of a million customers versus saying I prevented the disclosure of a million customers credit card numbers to the public?
Sorry, not prevented.
I found out that a million customers' credit card numbers
have been exposed to the public, and I plugged the hole.
Maybe don't say that part, but say we found this.
I don't know.
I think you can say I found a severe security vulnerability
and worked to get it fixed.
I guess it also depends on whether the company
has disclosed the vulnerability.
Because if they have, then you're probably safe to say,
I'm the one that found that.
And if they haven't, then I think you've got to be
a little bit more careful.
You're making me regret picking this question.
i don't know all the code i write is secure so i'm unfamiliar with this security vulnerability
concept you talk about yeah this is thanks to the no bugs driven development methodology that
we espouse yeah security security people love it when we call security a subset of bugs
we don't write bugs which automatically means our stuff is secure it's the
no vulnerability driven they're all smiling and nodding
yeah i i do think you were right to raise this question i do think it's an ethical quandary
i think it's very hard and i i would there i would definitely not do full disclosure here
there are definitely details i would reserve but it's going to be up to you to decide like what is
the exact details what's the point of this podcast then that's the biggest cop out i've ever heard
you say on this show oh that's not the biggest you said i don't know it's up to you i'm saying
i'm i'm kind of what i'm saying is not it's totally up to you i'm saying you're right
to not give all the details so on a spectrum of not revealing anything versus revealing all the
details it's you know in math how set notation has the bracket versus the parentheses around the set
the right hand side of this set has the one that excludes the final element whatever that is i
don't remember if it's a bracket is the uh it's the parens okay i just had to look this up yesterday
which is the only reason i know it so parens on the right hand side bracket on the left hand side
okay and our listeners all got it because they're all geniuses who also looked it up yesterday
okay i i feel like my the summary of my position is uh you should i buy your point about it sounds
much better if you have something to report more than like i found it and it's still there
yeah so try to get some progress on it and then i think it's okay to talk in vague terms about how
as part of your work you ran across these vulnerabilities that expose sensitive data
and and worked to get them fixed and it was kind of tricky to uncover them or whatever the story
you want to tell about it yeah i guess the story is it wasn't tricky to uncover them though the
story is it's shockingly open but i think i think it demonstrates that you care about improving
things that's great and and that you care about quality and doing good work and i think those
are good things to have stories to back up i agree all right well good luck i hope i hope
your job search goes well good luck and congrats on finding these awesome security vulnerabilities
congratulations yeah they're like pokemon you've acquired more your pokedex is more full now yeah
what should people do if they want their own questions answered go hit us up on our website
at softskills.audio and click on ask a question there's a simple form there thank you so much to
all of you who have asked questions this week. As usual, there's more than we can get to,
but we will eventually. Thank you so much for listening. See ya!
